NIS 2 Directive · 2022/2555

Article 21 measures. Article 23 timelines. One workspace.

STORM GRC gives CISOs, Heads of Compliance and DPOs at essential and important entities a single workspace for the cybersecurity risk-management measures, incident reporting workflow, supply-chain controls and management-body governance evidence NIS 2 requires.

Article 21 measures Article 23 reporting Supply-chain security (Art. 21(2)(d)) Article 20 governance
NIS 2 DIRECTIVE ENERGY BANKING HEALTH MARITIME DIGITAL MANUFACTURING FOOD RESEARCH ESSENTIAL IMPORTANT
NIS 2 · Scope & Readiness Live
Entity classification · Essential (Annex I) Confirmed
Article 21 measures · 10 / 10 mapped Complete
Supplier register · 14 missing assessments Action
Recognitions Independent awards for the STORM platform and its industry-specific implementations
Cyber Security Awards 2025 Gold
GoldMaritime cyber framework
Cyber Security Awards 2025 Silver – Integrated cyber services
SilverIntegrated cyber services
Cyber Security Awards 2025 Silver – GRC automation
SilverGRC automation
Cyber Security Awards 2025 Silver – Integrated cyber services
SilverBest Project – New Product (Risk Analysis)
Cyber Security Awards 2025 Silver – Integrated cyber services
SilverBest Use of Risk Technology & Platform
Cyber Security Awards 2025 Silver – Integrated cyber services
SilverBest Cybersecurity Risk Management
Compliance Awards 2025 Bronze – Best compliance platform
BronzeBest compliance platform
What changed with NIS 2

NIS 2 raises the bar for cyber governance: faster reporting, named accountability, and more organisations under supervision.

The Directive applies across the EU since the 17 October 2024 transposition deadline. Most operators discover they’re in scope, that personal accountability is real, and that incident timelines start in hours — not weeks.

SHIFT 01

Scope expansion

NIS 2 covers far more sectors than NIS 1 and pulls in medium-sized entities, not just large ones. Many organisations are now Essential or Important entities without realising it.

Annex I & Annex II
SHIFT 02

Article 21 measures

Ten categories of cybersecurity risk-management measures — from risk analysis to MFA, supply-chain controls and cyber hygiene — all evidenced and maintained on a continuous basis.

Art. 21 (1)–(4)
SHIFT 03

Article 23 timelines

Early warning to the CSIRT within 24 hours. Incident notification within 72 hours. Final report within one month. The reporting timeline begins as soon as the organisation becomes aware of a potentially significant incident.

Art. 23 reporting
SHIFT 04

Management liability

The management body must approve cybersecurity measures, oversee implementation and is personally liable for non-compliance. Cybersecurity training for the board is mandatory.

Art. 20 governance
Scope check

Essential or important — same obligations, different supervision.

Both categories carry the same Article 21 and Article 23 obligations. What differs is how the competent authority supervises you, and the maximum administrative fine.

Essential entities

Sectors of high criticality — energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, ICT service management, public administration, space.

  • Proactive supervisioncompetent authority can inspect at any time
  • Higher finesup to €10M or 2% of global turnover
  • On-site auditssecurity scans and document requests
  • Mandatory cybersecurity training for the management body
  • Same Article 21 measures as Important entities

Important entities

Other critical sectors — postal & courier, waste management, chemicals, food, manufacturing, digital providers, research organisations. NIS 2’s “important” category is still meaningful: you’re regulated, just supervised differently.

  • Ex-post supervision — triggered after incidents or evidence of non-compliance
  • Maximum fines up to €7M or 1.4% of global turnover
  • Same Article 21 measures, same Article 23 reporting
  • Same supply-chain obligations for downstream suppliers
  • Same management-body accountability rules
Article 21 measures

Ten cybersecurity risk-management measures. All mapped.

STORM’s NIS 2 configuration is pre-mapped to the ten Article 21 categories and the supporting governance and reporting requirements. STORM translates generic ISO 27001 controls into NIS 2 language so you don’t have to.

21.2.(a)
Risk analysis & system security policies
Policies on risk analysis and information system security — version-controlled, approved by the management body, traceable to identified risks.
Covered
21.2.(b)
Incident handling
Incident detection, classification, response and post-incident analysis — with the Article 23 24h / 72h / 1m reporting workflow built in.
Covered
21.2.(c)
Business continuity & crisis management
BCM, DRP, backup management, crisis-communication procedures — with BIA, RTO and RPO tracked at asset level.
Covered
21.2.(d)
Supply-chain security
Supplier register, security questionnaires, BitSight / FortiRecon ratings, contractual controls, sub-processor flow-down — directly downstream from Article 21.
Covered
21.2.(e)
Acquisition, development & maintenance security
Secure SDLC controls, vulnerability handling, configuration management — applied across procurement and engineering teams.
Covered
21.2.(f)
Effectiveness measurement
Policies and procedures to assess the effectiveness of cybersecurity risk-management measures, with the metrics auditors expect to see.
Covered
21.2.(g)
Cyber hygiene & training
Basic cyber hygiene practices for all staff and ongoing awareness training — including the GoPhish-integrated phishing simulation module.
Covered
21.2.(h)
Cryptography & encryption
Policies on cryptography use and encryption of data at rest and in transit, with control evidence pulled from MDM / EDR integrations.
Covered
21.2.(i)
HR security, access control, asset management
Joiner-mover-leaver workflows, access reviews, asset inventory and classification — populated from the same data model that drives risk assessment.
Covered
21.2.(j)
MFA & secured communications
Multi-factor authentication coverage, continuous authentication, secure voice / video / text communications and secured emergency communications.
Covered
Article 23 incident reporting

Three deadlines. One workflow.

From the moment your team becomes aware of a significant incident, the clock starts. STORM builds Article 23 into the incident module — so the early warning, the notification and the final report are produced from the same record without re-keying.

24h
Early warning

Notify the CSIRT

An early warning to the CSIRT or competent authority indicating whether the incident is suspected to be caused by unlawful or malicious acts, and whether it could have a cross-border impact.

72h
Notification

Full incident notification

An incident notification updating the early warning with an initial assessment of severity and impact, with indicators of compromise where available.

30d
Final report

Final report

A detailed description of the incident, its severity and impact, the type of threat or root cause, applied and ongoing mitigation measures, and (if applicable) the cross-border impact.

The NIS 2 workspace

What your CISO actually opens on Monday.

The same STORM platform, configured for NIS 2 — Article 21 measures cross-mapped to ISO 27001 you already have, Article 23 reporting wired into your incident module, supplier register linked to BitSight and FortiRecon.

STORM platform with NIS 2 framework mapped

Scope & entity check

A short configurator walks you through Annex I and Annex II to confirm whether you are Essential, Important, or out of scope — and which competent authority applies.

Article 21 gap analysis

Each of the ten Article 21 categories scored on the 5-level maturity scale, with drill-down to controls, evidence and remediation tasks assigned with deadlines.

24h / 72h / 1m timeline

Article 23 reporting wired into the incident workflow — the early warning, the notification and the final report all generated from the same record, with role-based approval and CSIRT-ready export.

Implementation

Audit-ready NIS 2 posture in 90 days.

A typical mid-size operator (essential or important entity, 200–1500 staff) hits NIS 2 audit-ready posture within one quarter. Larger operators with multiple subsidiaries plan a longer programme — but the first 30 days look the same.

30
days

Scope & baseline

  • Entity classification confirmed (Essential / Important)
  • Competent authority and CSIRT contact established
  • Article 21 gap analysis complete
  • Existing ISO 27001 controls mapped to Article 21
60
days

Measures & supply chain

  • Article 21 risk-management measures evidenced
  • Supplier register live with BitSight ratings
  • Incident response plan aligned to Article 23
  • Management body cybersecurity training delivered
90
days

Audit-ready

  • Internal audit completed and reported
  • Management body approval recorded
  • 24h / 72h / 1m reporting workflow tested
  • Competent authority documentation pack ready
NIS 2 implementation snapshot

From scattered controls to a management-ready NIS 2 evidence pack.

STORM gives essential and important entities one place to map Article 21 measures, supplier controls, incident-reporting workflows and management-body accountability. The result is a structured view of what is covered, what needs remediation and what can be shown to auditors or competent authorities.

NIS 2 readiness workflow Governance, evidence and reporting operations
Operation snapshot
Art. 21Cybersecurity measures mapped
Art. 23Incident reporting workflow
10/10Core measures evidenced
1Workspace for audit readiness
NIS 2 FAQ

Questions CISOs and Heads of Compliance actually ask.

If your question isn’t here, the answer is a 30-minute call — usually faster than email.

Are we essential, important, or out of scope?
It depends on the sector you operate in (Annex I or Annex II) and your size (medium = 50+ staff, >€10M turnover, or large).
We already have ISO 27001. Does that cover NIS 2?
ISO 27001 gives you a strong foundation and covers a large part of Article 21 — but NIS 2 goes further in three areas ISO doesn’t fully address: the mandatory incident reporting timelines under Article 23, supply-chain security obligations (Art. 21.2.d), and the direct liability placed on the management body. STORM imports your existing ISO 27001 SoA and risk register, maps them against NIS 2, and surfaces exactly where you have coverage and where you don’t.
How does the 24-hour early warning actually work?
When an incident is flagged in STORM, the early warning template is pre-populated with the fields the CSIRT expects. Your incident lead reviews, the DPO / CISO approves, and the early warning is exported in a CSIRT-ready format (PDF or per-MS form) within the 24h window. The same record carries through to the 72h notification and 1-month final report.
How do we handle suppliers under Article 21.2.d?
STORM’s TPRM module lets you classify suppliers by criticality, send tiered security questionnaires, layer in BitSight or FortiRecon ratings, and track contractual cybersecurity flow-downs. Each supplier file lives next to the risk it serves, so a supplier failure shows up in the right operational risk register.
Does the management body really need cybersecurity training?
Yes. Article 20 requires the management body to approve cybersecurity risk-management measures, oversee implementation and undergo training. STORM provides a short board-level training module, records completion, and produces the evidence pack regulators ask for during inspections.
Can we deploy on-premise?
STORM is delivered as a managed SaaS solution, hosted in EU-certified data centers. For organisations in critical infrastructure, public administration or defence with strict data-locality requirements, on-premise deployment can be discussed.
How is STORM priced for a NIS 2 programme?
STORM is licensed per organisation, scaled by user count and the frameworks you need. There are no per-document or per-report fees, and no separate charge for the Article 23 reporting workflow. We provide a fixed quote after a 30-minute scoping call so the year-one cost is clear before you commit.
Certifications

ICT PROTECT holds internationally recognised certifications across quality, security and assurance.

ISO 9001 · ISO 27001 · ISO 22301 · ISO 27701 ISAE 3000 Type I Cyber Essentials Certified and Cyber Essentials Plus
Get started

See STORM GRC supporting your NIS 2 obligations — in 30 minutes.

A focused demo with someone who knows the Directive. We walk through how STORM GRC supports Article 21 measures, Article 23 reporting, supply-chain controls and management-body governance evidence — and show you exactly how it fits your organisation, with no commitment required.

Book a 30-min demo

EU-based team. No sales pressure.